Google Sues Chinese Cybercrime Group for Gemini AI Cyberattacks
Key Takeaways Google has initiated a lawsuit against “Outsider Enterprise,” a China-based cybercrime organization. The group is accused of leveraging Google’s Gemini AI to generate...
Key Takeaways
- Google has initiated a lawsuit against “Outsider Enterprise,” a China-based cybercrime organization.
- The group is accused of leveraging Google’s Gemini AI to generate code for sophisticated phishing websites.
- This marks the first instance of Google pursuing legal action against threat actors for misusing its AI platform.
- The phishing campaigns targeted U.S. consumers, resulting in millions of smishing messages, thousands of fake websites, and significant financial losses.
- Google is seeking damages and injunctive relief while collaborating with telecommunication carriers and advocating for new legislation to combat AI-driven scams.
Google Takes Legal Action Against AI-Enabled Cybercrime Network
In an unprecedented move, Google has filed a lawsuit against a Chinese cybercrime syndicate known as “Outsider Enterprise.” This legal challenge represents the first time the tech giant has pursued legal recourse against threat actors specifically for weaponizing its Gemini AI platform. The lawsuit alleges that Outsider Enterprise utilized Gemini to orchestrate extensive phishing campaigns targeting consumers across the United States.
Table Of Content
Outsider Enterprise operates as a sophisticated phishing-as-a-service (PhaaS) provider, facilitating large-scale criminal operations. The network coordinates its activities primarily through Telegram channels, distributing pre-packaged phishing kits to a broad affiliate base of cybercriminals.
This network equips individuals with minimal technical expertise to rapidly deploy highly convincing fraudulent websites. These sites impersonate a wide array of trusted entities, including Google, YouTube, the U.S. Postal Service, various financial institutions, state DMVs, and toll collection agencies such as New York’s E-ZPass. The group provides a comprehensive library of over 290 prebuilt templates to facilitate these scams.
Gemini AI Abused to Generate Malicious Code
What sets Outsider Enterprise apart from typical phishing operations is its deliberate exploitation of artificial intelligence. According to Google’s legal complaint, members of the cybercrime group actively encouraged each other to use Gemini to generate custom code for their phishing websites. This malicious code was then directly integrated into the Outsider software suite, transforming it into live scam pages. General Counsel DeLaine confirmed these details to The New York Times.
By leveraging Google’s generative AI, the Enterprise effectively industrialized fraud, drastically lowering the technical bar for creating sophisticated scam infrastructure. This turned Gemini into a factory for malicious code, streamlining the creation of fraudulent online presences.
The scale of the alleged criminal activity and its impact is substantial:
- Over a two-week period in May 2026, 2.5 million smishing messages were sent to Android users.
- During the same two-week span, Android users flagged 55,000 spam texts, indicating a rate of more than two complaints per minute.
- The network is linked to more than 9,000 fake websites and over 1 million fraudulent URLs.
- Hundreds of thousands of victims have reportedly suffered financial fraud, with estimated total losses reaching millions of dollars.
Google formally filed the complaint in the U.S. District Court for the Southern District of New York. The company is seeking both damages and injunctive relief under the Racketeer Influenced and Corrupt Organizations (RICO) Act and the Lanham Act.
In a parallel effort, the FBI’s Cyber Division is conducting its own law enforcement actions. Assistant Director Brett Leatherman noted that criminals are “increasingly use AI to make fraud more convincing and harder to detect.” Concurrently, Google is collaborating with major U.S. carriers, including AT&T, T-Mobile, and Verizon, to intercept and block these fraudulent messages before they can reach end users.
Google is also actively supporting seven bipartisan legislative proposals aimed at combating AI-driven scams. Among these is the Stop SCAMS Act, championed by Congressmen Brian Fitzpatrick and Josh Harder, which seeks to establish a national coordinated strategy involving law enforcement, government agencies, and private industry to counter transnational cybercrime organizations.
From a product standpoint, Google’s AI-powered scam detection features on Android actively identify suspicious conversations during calls. Furthermore, the company’s built-in messaging defenses currently block over 10 billion malicious messages each month. Google has also taken steps to disable Gemini accounts and associated infrastructure confirmed to be involved in the abuse of its AI model.
This lawsuit establishes a significant legal precedent, indicating that AI platforms can serve as grounds for civil litigation when threat actors exploit generative models to scale their criminal operations. This action signals a new and critical front in the ongoing battle against AI-enabled cybercrime.
What You Should Do
- Be skeptical of unsolicited messages: Exercise extreme caution with unexpected texts or emails, even if they appear to be from trusted organizations.
- Verify sender identity: Always independently verify the sender’s identity through official channels (e.g., calling the organization directly using a number from their official website) before clicking links or providing information.
- Enable multi-factor authentication (MFA): Secure all online accounts with MFA to add an extra layer of protection against credential theft.
- Report suspicious messages: Utilize built-in reporting features in messaging apps and email clients to flag suspicious communications.
- Keep software updated: Ensure your operating systems, applications, and security software are always up to date to protect against known vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.